Days of Cover Privacy Policy
Effective Date: July 29, 2026 · Last Updated: August 4, 2026 · Version: 1.2
The version and date above are the operative ones.
1. Introduction; Scope
1.1. This Privacy Policy (this "Policy") describes the practices of WeLynk LLC, a limited liability company organized under the laws of the State of Alabama (the "Company," "we," "us," or "our"), with respect to the collection, use, processing, retention, and disclosure of information in connection with Days of Cover, a Shopify application that tells merchants which products to reorder, when, and in what quantity, and shows the arithmetic behind every such recommendation, together with the Company's related servers, websites, and electronic mail communications (collectively, the "Service").
1.2. The Service is a business-to-business application made available to merchants ("Merchants," "you," or "your") that operate online stores on the Shopify platform ("Shopify"). This Policy applies to information processed through the Service. It does not apply to Shopify's own processing of your data, which is governed by Shopify's agreements and privacy policy, nor to any other product or service of the Company.
1.3. Controller and processor roles. With respect to a Merchant's account and contact information, the Company acts as a controller. With respect to the store data that the Company accesses from a Merchant's Shopify store in order to provide the Service, the Company acts as a processor and service provider on the Merchant's behalf and under the Merchant's instructions, and processes such data solely to provide the Service and for no independent purpose of the Company. As between a Merchant and the individuals whose data may appear in store records, the Merchant is the controller.
2. Information the Service Accesses from Shopify
2.1. Authorized scopes. Upon installation, the Service requests four Shopify access scopes and no others: read_products, read_orders, read_inventory, and read_locations. Every one is read-only. The Service holds no write scope of any kind and is therefore incapable of altering a Merchant's inventory, products, or orders. A purchase order produced by the Service is a document the Merchant sends, not an action the Service takes within the store. The Service declares no optional scopes.
2.2. Order data. Under the read_orders scope, the Service subscribes to order webhooks declaring a field restriction (include_fields), so that Shopify delivers only the following top-level fields: the order identifier, the created, updated, processed, and cancelled timestamps, the financial status, the currency, the test-order flag, and the line items. The restriction is named here so that a reader may verify it against the Service's published webhook declarations rather than take this sentence on trust.
That restriction operates on top-level fields only, and the Company states the consequence rather than leaving it implied. No customer object is delivered at all, which is what places the customer's personal information beyond the reach of any error in the Company's own code. But each line item is delivered complete, including the properties attribute array, which is the standard carrier for personalization text a shopper enters, such as a gift-message name, an engraving, or a delivery instruction. That text can constitute personal information.
The Company therefore performs a second reduction of its own, on receipt and before anything else happens to the payload. Every order webhook body is projected at the edge down to the fields the demand calculation requires, being the line-item identifier, the variant identifier, the quantity, and the unit price. The raw body does not reach a background job, a log entry, or any table. This is a control the Company operates and is obliged to maintain; it is not a property of the Shopify platform.
Of the foregoing, the Service retains the order and line-item identifiers, the variant identifier, the quantity, the unit and line prices, the store-local date of the order, whether the line counts toward demand, and Shopify's own last-updated timestamp for the order.
Access to order data constitutes access to Protected Customer Data at Level 1 under Shopify's Protected Customer Data requirements, and the Company maintains the corresponding data-use declaration with Shopify. The Company has not applied for, and will not apply for, Level 2 access, including for the purpose of obtaining inventory history.
2.3. Product and catalog data. Under the read_products scope, the Service accesses the Merchant's product catalog, including product and variant titles, stock-keeping units, vendors, product types, retail prices, and Merchant-entered unit costs.
2.4. Inventory and location data. Under the read_inventory and read_locations scopes, the Service accesses inventory quantities and the store's stock locations. These scopes exist because the Service's function is to predict when a product will run out, which cannot be computed without knowing how much of it exists and where.
2.5. Store record. At installation, and thereafter at most once in any twenty-four (24) hour period, the Service reads the store's own record, namely its Shopify store identifier, store name, time zone, currency, and the store and contact electronic mail addresses that the store publishes to installed applications. The store name is read because it appears on a purchase order the Merchant sends to a supplier, as described in Section 7.6. That interval is shortened only where an erasure request is outstanding for the store, because in that circumstance the read is itself the evidence described in Section 9.5. The time zone is required because the Service computes every figure in the store's own local day; a calculation performed in any other time zone silently misattributes a day's sales. The electronic mail address is retained as described in Section 4.1 and used only as described in Section 5.6. Where a store does not make these addresses available, the Service continues to operate without them.
3. Information the Service Does Not Collect
3.1. The Service is designed so that it does not process, store, or retain the personal information of a Merchant's customers. The Company does not access, request, or store customer names, electronic mail addresses, physical or billing addresses, telephone numbers, or customer identifiers. Any shopper-entered line-item attribute that Shopify delivers is discarded at the edge, as described in Section 2.2, before it is enqueued, logged, or persisted.
3.2. This is enforced by construction rather than by undertaking, in two independent ways. First, every order webhook to which the Service subscribes declares a field restriction, with the consequence that Shopify does not transmit a customer object to the Company at all; a defect in the Company's code therefore cannot expose one. Second, no query the Service issues selects a customer field. Both are verifiable by inspection of the Service's webhook declarations and of its queries respectively. The Company does not construct profiles of, and does not track, any Merchant's individual shoppers.
3.3. The Service is embedded within the Shopify administrative interface and authenticates each request using Shopify session tokens. The Service does not employ advertising cookies, meaning cookies used to select, serve, or target advertising, nor cross-site tracking technologies, third-party behavioral analytics, or tracking of individuals across websites or services. The Service does measure its own product usage and its own electronic mail, as described in Section 4.9: that measurement is first-party, is recorded against the store's domain rather than against any individual, uses no third-party analytics provider, sets no cookies, and does not follow anyone beyond the Service's own pages and messages.
3.4. The Company's public website stores nothing on a visitor's device. It sets no cookie of its own, uses no local storage, and reads nothing back from the device on a later visit. Where a visitor arrives by way of a link the Company has tagged, being an advertisement, a search listing, or a referral from a partner, the Company records which of a short fixed list of channels that link belonged to; that value exists only for the duration of that visit, being carried within the Company's own pages, and is written to the Company's records only if the visitor goes on to install the Service or to join the waitlist. Nothing is placed on the visitor's device at any point, and a visitor who reads the site and leaves is not recorded at all.
The Company designed it this way deliberately, rather than seeking consent to store a cookie, and states the consequence honestly: a visitor who arrives by a tagged link, leaves, and returns later cannot be connected to their earlier visit, and the Company does not attempt to do so.
The Company's public website is served through a content delivery network, which may set its own short-lived cookies for security and abuse prevention, being the detection of automated traffic. Those are set by that provider, are strictly necessary to serving the site safely, carry no information the Company puts there, and are not used by the Company for any purpose. The provider is identified in Section 7.
4. Information Stored by the Service
The Company stores the following categories of information for the purpose of providing the Service:
4.1. Merchant and store information: the store's myshopify.com domain, Shopify store identifier, store name, time zone, currency, plan status, and installation state; the electronic mail address a Merchant optionally provides in order to receive the messages described in Sections 5.4 and 5.5, and the store contact address described in Section 2.5; a record of whether, and when, a Merchant has asked the Company to stop sending the messages described in Section 5, and of when each such message was last sent; and operational timestamps recording when the Service last completed an authenticated load for the store, when Shopify last delivered a webhook for it, and whether and when Shopify requested erasure, all of which exist so that the Service can distinguish a store that is still in use from one that has gone (see Section 9.5) and none of which describes any individual;
4.1A. Configuration and operational counters: settings a Merchant enters, being the reorder budget, the default lead time, the default safety-stock percentage, the digest frequency and send day, and the primary location; together with counters the Service maintains for plan enforcement and scheduling, being the tracked-variant and location counts, whether and since when a store has exceeded its plan limit, the date from which history is held, and whether the initial import has completed. The reorder budget is a financial figure concerning the Merchant's business and is stated here for that reason. None of the foregoing describes any individual;
4.2. Shopify access credentials: the offline access token issued at installation, together with the refresh credential and its expiry where Shopify issues one, which the Service uses to read the store on the Merchant's behalf. The Company's session records additionally declare fields that exist only for Shopify's "online" access tokens, being a staff member's Shopify user identifier, first name, last name, electronic mail address, account-owner status, collaborator status, electronic mail verification status, and locale. None of those fields is ever populated, because the Service uses offline tokens exclusively and never requests an online one;
4.3. Product, variant, location, and cost records: catalog data as described in Section 2.3, together with unit costs and supplier lead times and, for each such value, the source from which it came, being Merchant-entered, imported from Shopify, imported from a Stocky export, or estimated as described in Section 6;
4.4. A daily inventory history. One record per tracked variant, per location, per store-local day, from installation onward, retained indefinitely for so long as the Service remains installed. This is the Service's core dataset and the reason it is able to tell a Merchant what a past stockout cost them. It exists because Shopify exposes no inventory history of its own, and the Company has declined to seek the elevated data access that would be required to obtain one; the Service therefore constructs its own by recording a reading each day. It is an ongoing time series rather than a mirror of current state, and the Company states so rather than allowing Section 4.3 to understate it;
4.5. Order financial records: the order line-item fields enumerated in Section 2.2, stored without customer-identifying information;
4.6. Derived figures: daily sales rollups, computed stockout periods, forecast runs, and the reorder recommendations produced from them, together with the inputs and provenance of each, so that the arithmetic behind any recommendation can be displayed to the Merchant on request;
4.7. Purchase orders and supplier contact addresses: purchase orders a Merchant builds, and the supplier electronic mail addresses a Merchant enters in order to send them. A supplier address is stored against the vendor record so that a Merchant need enter it only once, and is reused for subsequent orders to that supplier. This is third-party personal information supplied by the Merchant, and its disclosure is described in Section 7.6;
4.8. Import records: where a Merchant imports a Stocky export, the Service retains the uploaded file's name and any row-level errors, which quote cells from the Merchant's own file so that the Merchant can locate and correct them. The uploaded file itself is never written to disk;
4.9. Product-analytics events: a record of significant events in the Service's own lifecycle, so that the Company can measure whether the Service works for the Merchants who install it. Each record consists of the application name, the store's myshopify.com domain, an event name drawn from a fixed list (for example, that the application was installed, that the initial import finished, that reorder settings were confirmed, that a reorder list was first viewed, that a purchase order was first exported, that a subscription began, that a message was sent, opened, or clicked, or that the application was uninstalled), a timestamp, a small set of non-textual properties, being numbers, true/false values, values drawn from fixed lists, and two short strings that are neither free text nor personal data: the date a message covered, and the campaign label described in Section 4.10; and a de-duplication key. These records contain no customer information, no free text, and nothing a Merchant types. They are stored in the Company's own database and are not transmitted to any third-party analytics provider. Where an event relates to electronic mail, it is recorded by a one-pixel image or by a redirect through the Company's own servers, as described in Section 3.3; and
4.10. Outreach list: where the Company has contacted a store directly, the store's myshopify.com domain and a campaign label, entered by the Company by hand, so that an installation may be attributed to that outreach. This list contains publicly available store domains only, and concerns stores that have not installed the Service. It is deleted when a store's data is purged, and upon an erasure request for a domain that never completed installation; and
4.11. Waitlist addresses: where a visitor to the Company's public website chooses to leave an electronic mail address in order to be told when the Service becomes available on the Shopify App Store, that address and the date it was left, together with the channel described in Section 3.4 where the visitor arrived by a tagged link. This is the only information the Company stores about a person who is not a Merchant and has installed nothing. It is stored for one purpose, being to send that single announcement, and is used for no other; it is never transmitted to any third party; and it is deleted on request to the address in Section 13, or once the announcement it exists for has been sent and the Company has no continuing reason to hold it. A repeated submission of the same address does not create a second record; and
4.12. Referral channel: where a Merchant reaches the Service by way of a tagged link as described in Section 3.4, the channel and campaign label that link carried, recorded against the store's myshopify.com domain and, once the store installs the Service, against the store's own record together with the time of that visit. This exists so that the Company can tell which of its own efforts bring Merchants to the Service. It describes a link, not a person: it contains no identifier for any individual, no free text, and nothing a visitor or Merchant types, both values being drawn from fixed lists the Company maintains and anything else being discarded. Where a Merchant reaches the Service without such a link, which includes finding it in the Shopify App Store, no such record exists and none is created. Retention is described in Section 9.8.
5. Purposes of Processing
The Company processes the information described in this Policy solely for the following purposes:
5.1. to compute and present the Merchant's reorder recommendations, days of cover, reorder points, suggested quantities, and related figures within the Service;
5.2. to present, on request, the arithmetic from which any such figure was derived, including which days were excluded from a velocity calculation and why;
5.3. to estimate missing unit costs and supplier lead times by the automated means described in Section 6;
5.4. to compose and deliver the optional reorder digest to the electronic mail address a Merchant provides. That message identifies the Company by name and postal address and carries a link by which the Merchant may stop it in a single action without signing in, as described in Section 5.8;
5.5. to send, at most once every calendar month, a summary of what being out of stock is estimated to have cost that store in the preceding month, broken down by product. That message is sent only to the address a Merchant provided as described in Section 4.1, states why it was received, identifies the Company by name and postal address, and carries the same one-click stop link;
5.6. to send a single message after a store uninstalls the Service, asking why, so that the Company can improve the Service. That message is sent at most once per installation, is never followed by any further message or sequence of its own, is not sent at all where the Merchant has asked the Company to stop writing to them, states why it was received, identifies the Company by name and postal address, and is addressed to the digest address where one was provided and otherwise to the store contact address described in Section 2.5. The Company honors a reply asking that it not write to an address again;
5.7. to operate, secure, maintain, and support the Service, and to comply with applicable law and with the Company's obligations to Shopify; and
5.8. The one-click stop request is sitewide. A single request stops every message the Company sends about that store, being the digest described in Section 5.4, the monthly summary described in Section 5.5, and the message described in Section 5.6. The Company records and honors that request for so long as it holds the store's records. A Merchant who wishes to resume may do so by saving a different digest address in the Service's settings, which the Company treats as renewed consent. Clearing the digest address is not consent and does not resume anything; nor does re-saving an address the Merchant had already saved. The Company further states, because the contrary assumption would be reasonable and wrong, that clearing the digest address does not by itself stop the message described in Section 5.6, which falls back to the store contact address; only the one-click stop request does that.
The Company does not sell information, does not share information for advertising, and does not use store data for any purpose other than providing the Service.
6. Automated Cost and Lead-Time Estimation
6.1. Most small stores have never populated Shopify's unit-cost field. Where a product lacks a Merchant-entered, Shopify-imported, or Stocky-imported value, the Service may estimate one using an artificial-intelligence service provided by Anthropic, PBC ("Anthropic"). Three values are estimated in this way: the landed unit cost, the reorder lead time, and the safety-stock fraction, that last being the buffer the Service holds against variability in demand.
For this purpose the Company transmits the following and nothing further:
(a) for each variant: the product title, the variant or option title, the vendor, the product type, the retail price, and the Company's own internal variant identifier; and
(b) for the store as a whole: its currency, the maximum lead time the Service will accept, and the Merchant's own default safety-stock percentage, each of which is required for the estimate to be expressed in terms that apply to that store.
6.2. The Company does not transmit order data, sales or financial totals, inventory data, purchase orders, supplier contact information, or any customer information to Anthropic, and no such data is included in any prompt. Of text a Merchant has written, only the catalog fields enumerated in Section 6.1(a) are transmitted: no note, comment, or other free-text field a Merchant enters elsewhere in the Service is sent.
6.3. Anthropic processes such data on the Company's behalf as a service provider, subject to contractual restrictions that prohibit use of the data to train Anthropic's models or for Anthropic's own purposes.
6.4. Every estimated value is identified as an estimate within the Service, displays the source from which it came, and may be overridden by the Merchant at any time. A value a Merchant sets is never overwritten by an estimated or automated one.
7. Sub-processors and Disclosures
7.1. Sub-processors. The Company engages the following service providers, each of which processes information on the Company's behalf, for the purposes described in this Policy, under written contracts that restrict processing to the Company's instructions and require appropriate confidentiality and security:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting (compute and database), transactional electronic mail delivery, and secrets storage | United States (us-east-1) |
| Cloudflare, Inc. | Edge network, transport-layer security, and denial-of-service protection. Every request to the Service passes through it | United States / global |
| Anthropic, PBC | Automated cost and lead-time estimation (product metadata only; see Section 6) | United States |
7.2. Shopify is the platform on which the Service operates and is not a sub-processor of the Company; Shopify's processing of a Merchant's data is governed by Shopify's own agreements.
7.3. Legal disclosures. The Company may disclose information where it believes in good faith that disclosure is required or permitted by applicable law, including in response to valid legal process, to protect the rights, property, or safety of the Company or others, or to enforce the Company's agreements.
7.4. Corporate transactions. In connection with any merger, acquisition, financing, reorganization, or sale of all or a portion of the Company's assets, information may be transferred to the parties to such transaction and to a successor entity, subject to this Policy or a successor policy.
7.5. No sale; no advertising. The Company does not sell information, does not share information for cross-context behavioral advertising, and does not disclose information to any third party for such third party's own marketing or advertising purposes, and has not done so during the twelve (12) months preceding the Effective Date of this Policy.
7.6. Disclosure to a supplier the Merchant chooses. Where a Merchant sends a purchase order from within the Service, the Company transmits, on that Merchant's instruction, an electronic mail message to the supplier address the Merchant entered. That message discloses to that supplier: the store's name; the stock-keeping units and product titles on the order; the quantities ordered; the unit costs, the line totals and the order total; any free-text note the Merchant added to the order; and the Merchant's own contact address, which appears both as the reply-to address and in the body of the message so that the supplier knows where a reply will go. The complete purchase order is additionally attached to the message as a document. The Merchant is the controller of that disclosure, both as to the store data disclosed and as to the supplier's contact information, which the Merchant supplied. That message is transactional: it is sent because the Merchant pressed a button, exactly one message is sent per instruction, and it therefore carries no stop link and no open tracking.
8. Data Location and Security
8.1. Information processed by the Service is stored on infrastructure operated by Amazon Web Services in the United States (the us-east-1 region).
8.2. The Company maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, including: encryption of data in transit using Transport Layer Security; encryption of data at rest on the Company's database volume; restriction of the application origin at the network layer so that it is reachable only through the Company's edge network; the absence of any interactive shell service on the application server, administrative access being conducted instead through an audited session service; verification of the authenticity of Shopify webhooks by cryptographic signature; storage of runtime secrets in a managed secrets service rather than in configuration files; and access controls limiting personnel access to information necessary to their functions.
8.3. Credentials are excluded from logs by construction. The Service's access logs record the path, status, and size of a request but discard the entire query string and the referring page, rather than filtering a list of named parameters. This is deliberate: the Service's own electronic-mail links and Shopify's session tokens are both carried in the query string, and a filter enumerating known parameter names would fail to exclude the next such parameter that Shopify introduces.
8.4. No security program eliminates risk entirely, and the Company does not warrant or guarantee the absolute security of any information.
8.5. Security incidents. In the event of a breach of security resulting in unauthorized access to or disclosure of information processed through the Service, the Company will notify affected Merchants and, where required, applicable regulators, in the manner and within the time periods required by applicable law, and will take reasonable measures to contain and remediate the incident.
9. Data Retention and Deletion
9.1. Order, product, inventory, cost, purchase-order, and derived records are retained for so long as the Service remains installed on the store, and are deleted upon uninstallation as described in Section 9.2. The daily inventory history described in Section 4.4 is retained on the same basis.
9.2. Uninstallation. When a Merchant uninstalls the Service, the stored Shopify access credential is deleted immediately and the store's data is scheduled for deletion. Reinstallation within the recovery window cancels the pending deletion, so that a Merchant who uninstalls and reinstalls does not lose configured costs, lead times, and settings.
9.3. Product-analytics events are pseudonymized rather than deleted. The records described in Section 4.9 are treated differently, and the Company states the difference plainly. At deletion, the store's myshopify.com domain in those records is replaced with an irreversible-in-practice keyed hash and the de-duplication key is cleared; the rows themselves are then retained, so that historical measurements of the Service do not disappear. This is pseudonymization, not anonymization. myshopify.com domains are public and can be enumerated, so a party holding the Company's hashing key could reconstruct the mapping. The Company holds that key in a managed secrets service under its sole control, holds a key distinct from that of any other application it operates, and treats it with the same sensitivity as the data it protects. The retained records contain no customer information and no Merchant-entered text.
Where that key is unavailable at the moment an erasure must be completed, the Service deletes the records outright instead of pseudonymizing them. The Company states this because the alternative would be to retain identifiable records past an erasure obligation, and deletion is the safer failure.
9.4. Shopify compliance webhooks. The Company honors the mandatory Shopify compliance webhooks.
A customers/redact request is satisfied without further action, and the Company states the reasoning rather than only the outcome. The Service stores no customer identifier of any kind: no name, electronic mail address, telephone number, postal address or customer identifier is received, logged or retained, in any record. What the Service does retain for each order is one record per line of that order, carrying the store's own order identifier, the product variant, the store-local date, the quantity and the unit price, and nothing else. Those records identify a product and a day; no shopper is attached to them, and the Company holds nothing by which one could be. Re-identification would require the store's own order records held by Shopify, which are the Merchant's data and not the Company's. The Company does not delete those records on such a request, because doing so would destroy the demand history the Service exists to compute from, and would erase no personal information, there being none to erase.
A customers/data_request is answered on the same basis: the Company holds no information about the identified shopper to return.
A shop/redact request results in deletion of the store's data on the terms set out in Sections 9.2, 9.3, and 9.5.
9.5. A store that returns discharges an erasure request, and the Company states that plainly rather than omitting it. Shopify issues a shop/redact request approximately forty-eight (48) hours after an uninstallation, and delivers it only once. It therefore routinely reaches stores whose Merchant has since reinstalled the Service.
Where the Company has recorded an uninstallation for the store, the ordinary recovery window in Section 9.2 applies and the data is deleted once it has elapsed.
Where the Company has recorded no uninstallation, which is the reinstallation case, deletion is not recoverable and the request is not acted upon immediately. The Company records the request durably and observes the store for a period falling within the thirty (30) days Shopify allows for completion. If, during that period, the store demonstrates that the Service is installed and in use, the request is treated as discharged: the store's data is retained, and the electronic mail described in Section 5 resumes.
A store demonstrates use in either of two ways, each requiring a request authenticated by Shopify, and the two are not subject to the same condition:
(a) a Merchant opening the Service within the Shopify admin, which counts immediately; or
(b) Shopify delivering a webhook of a kind it sends only to installed applications, which counts only where it arrives at least forty-eight (48) hours after the request, that margin existing because a webhook queued before the request may be delivered after it and is therefore no evidence of a return.
A store that is genuinely gone produces neither signal and is erased within Shopify's mandatory thirty (30) day window.
The Company states this exception because a policy asserting unconditional deletion within thirty (30) days would be inaccurate in the reinstallation case, and an inaccurate statement in a privacy policy is a more serious defect than an omitted one. A Merchant's request to stop receiving electronic mail is a separate matter and is unaffected by any of the foregoing.
9.6. Supplier contact addresses stored under Section 4.7 are deleted with the store's other records on the terms set out in Section 9.2.
9.7. Backups, and the window in which deletion is not yet complete. The Company maintains encrypted backups of its database so that the Service can be restored following a failure of the storage holding it. A backup is retained for no more than thirty (30) days and expires automatically. The Company maintains no archival copy and no copy of indefinite duration.
Deletion under Sections 9.2, 9.3, and 9.5 is performed against the live database. A store's records may therefore persist within a backup taken before that deletion, for the remainder of that backup's retention period, and in no case for longer than thirty (30) days after the deletion. The Company states this rather than omitting it, because a policy describing deletion as instantaneous and total would be inaccurate for any service that keeps a backup at all.
A backup is not used to reinstate records the Company was required to erase, and the Company does not restore a backup in order to recover records it has erased. Backups serve one purpose, being the reconstitution of the Service following a loss of its production database, and restoring one is a measure of last resort.
The Company states the limit of that undertaking rather than implying a stronger one. A restoration performed after such a loss may return records erased after the restored backup was taken, because the record of the erasure is itself held in the database being restored. Where the Company holds a record of such an erasure, it is carried out again before the Service resumes.
9.8. Referral channel. The record described in Section 4.12 exists in two forms and both are bounded. Nothing is held on the visitor's device at any stage (Section 3.4). The staged form, held on the Company's own servers against a store's myshopify.com domain from the moment a Merchant begins installation, is deleted when the installation completes, which is ordinarily within seconds, and in every case automatically within one (1) hour of being created, whether or not any installation followed. It is also deleted on an erasure request for that domain in the meantime. The recorded form, held against the store's own record once the Service is installed, is deleted with the store's other records on the terms set out in Section 9.2.
10. Rights
10.1. Merchants. A Merchant may (a) uninstall the Service at any time, which initiates deletion of the store's data as described in Section 9; (b) request access to, correction of, export of, or deletion of the information the Company maintains; (c) stop every message described in Section 5 in a single action, as described in Section 5.8; and (d) contact the Company with any question concerning this Policy. Requests may be submitted to admin@welynk.com. A request raised through Shopify's own privacy tooling reaches the Company directly and is handled by the endpoints described in Section 9.4.
10.2. Individuals whose data appears in store records. Because the Company processes store data as a processor on the Merchant's behalf, and does not store customer-identifying information, an individual seeking to exercise rights with respect to a store's records should direct the request to the Merchant that operates the store, which is the controller of such records. The Company will assist the Merchant in responding to such requests as required by applicable law and by the Company's obligations to Shopify.
10.3. Suppliers. A supplier whose contact address a Merchant has entered into the Service, and who wishes to have that address removed, should direct the request to the Merchant that entered it, which is the controller of that information as described in Section 7.6. The Company will assist the Merchant in giving effect to such a request.
11. International Users
The Service is operated from the United States, and information is processed and stored in the United States, where data-protection laws may differ from those of your jurisdiction. By installing or using the Service, you acknowledge that information will be transferred to and processed in the United States as described in this Policy.
12. Changes to This Policy
The Company may amend this Policy from time to time. In the case of a material amendment, the Company will indicate the change by an updated "Last Updated" date and, where appropriate, provide notice to Merchants by electronic mail or within the Service. Your continued use of the Service following the effectiveness of an amendment constitutes your acknowledgement of the amended Policy.
13. Contact
Inquiries and requests concerning this Policy or the Company's data practices may be directed to:
Privacy requests, data requests, legal matters, and support: admin@welynk.com
One address, deliberately. It is the address the Service itself displays to Merchants, so it is the one the Company can be certain reaches a person. A policy that lists departmental addresses which bounce is worse than a policy that lists one that does not.
Mailing address:
WeLynk LLC c/o Northwest Registered Agent Service, Inc. 212 W. Troy St. STE B Dothan, AL 36303
© 2026 WeLynk LLC. All rights reserved.